JG BioConsult, LLC

CMC, GMP and Quality Consulting for the Biotech Industry

Data Integrity, Again

Data Integrity (DI) is still here, and still important to FDA, even though it seems to have been important for a long while now, as the FDA guidance document came out 8 years ago.  What are the approaches to DI and how can a company try to limit possible FDA observations around DI?  The answers can be complicated, but a practical approach can also be taken.

Most people understand what DI is after reading the guidance, which addresses DI in part as data which has ALCOA characteristics:  data are attributable (we can figure out who entered the data), data are legible (can read it if written), data are contemporaneous (recorded at the time of completion), data are in the original (copies are an exact duplicate and we can figure out which is the original), and data are accurate (complete and true).  There are other standards which are expected, like data controls ensuring completeness, data backups, etc.

Many DI issues occur in the GMP lab, and DI controls are a cGMP requirement. For example, when we consider instrument level DI, it is expected that instruments have unique IDs and passwords for all users, and have an audit trail for all cGMP tests, and that the data are backed up.  In addition, use of USB drives is considered a risk area.

Is all this sounding too complicated?  Yes, it is.  One approach is to perform a risk assessment for DI at the site, which considers all the computer systems in use for GMP and the controls around them, and asks the question if the controls are sufficient to satisfy the cGMP requirements in the guidance.  Having this risk assessment will allow the company to come up with additional controls as needed and formalize them within the quality system.  It is also a good idea to have a DI SOP or policy which could be based on this risk assessment, the guidance, or ideally both.

Having adequate controls around DI for cGMP can feel overwhelming, but taking a step-by-step approach is best. A risk assessment is the first step, and then formalizing additional controls in an SOP or policy is the second step.  Of course, then complying with the SOP or policy can also generate additional work, because there could be some gaps to address like completing additional validation, purchasing software that is cGMP compliant and validating it, or purchasing equipment that complies with the new DI policy.

If you are not sure where to start, or need a DI risk assessment, or an assessment of DI compliance at your site, a consultant can help with all of these tasks. Assessing the risk of DI non-compliance is important for both new products (preapproval inspections) and ongoing products (biennial inspections) in order to minimize DI observations.

Next Post

Leave a Reply

© 2026 JG BioConsult, LLC

Theme by Anders Norén